CVE-2016-6341

MEDIUM

oVirt Engine <4.0.3 - Info Disclosure

Title source: llm

Description

oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (2)

ovirt/ovirt < 4.0.2
n/a/n/a

Timeline

Published Apr 20, 2017
Tracked Since Feb 18, 2026